Privacy Policy
Last updated: November 1, 2025This Privacy Policy explains how Miseru ("we," "us," or "our") collects, uses, and protects information in connection with our AI-powered product tour generation platform (the "Service"). We are committed to protecting your privacy and being transparent about our data practices.
1. Scope and Data Processing Roles
This Privacy Policy applies to three distinct groups of individuals who interact with our Service:
- Website Visitors: Individuals who visit our website at miseru.ai. For these visitors, Miseru acts as a Data Controller.
- Customers: Organizations and individuals who register for and use our Service. For Customer account data, Miseru acts as a Data Controller.
- End-Users: Individuals who interact with our Customers' applications where our Service has been installed. For End-User data processed through our Service, Miseru acts as a Data Processor on behalf of our Customers.
If you are an End-User of a Customer's application, your personal data is controlled by that Customer, and you should refer to their privacy policy for information about how they handle your data. This Privacy Policy describes how we process that data on their behalf.
2. Information We Collect
2.1. From Website Visitors
When you visit our website, we collect:
- IP addresses
- Browser type and version
- Device information and operating system
- Location data (city, region, country)
- Pages visited and navigation patterns
- Referrer information
- Cookies and similar tracking technologies
2.2. From Customers
When you register for and use our Service, we collect:
- Account Information: Name, email address, company name, billing information, and contact details
- Authentication Data: Passwords (encrypted), API keys, and session tokens
- Usage Data: How you use the Service, features accessed, tours created, and configuration settings
- Communication Data: Messages, support requests, and feedback you send to us
- Payment Information: Billing details and payment method information
2.3. From Customer Applications (End-User Data)
When our Service is installed on a Customer's application, we collect and process data to generate product tours, including:
- Application interface structure and visual elements
- User interactions and navigation patterns
- Content elements necessary for generating contextual tours
- Questions submitted by End-Users to trigger tour generation
2.4. Important Notice About Personally Identifiable Information
Our Service analyzes Customer applications to generate product tours. In doing so, we may inadvertently capture personally identifiable information (PII) that is visible in the application interface.
Customer Responsibility: Customers are responsible for ensuring that sensitive or regulated PII is not exposed during tour generation. We recommend that Customers:
- Use test or demo environments with anonymized data when possible
- Configure the Service to exclude sensitive areas of their application
- Review generated tours before making them available to End-Users
- Contact us to establish a Data Processing Addendum if processing regulated data (see Section 10)
3. How We Use Your Information
3.1. Website Visitor Information
We use information from website visitors to:
- Understand how visitors use our website
- Improve our website and user experience
- Analyze traffic patterns and visitor behavior
- Detect and prevent fraud or security issues
3.2. Customer Information
We use Customer information to:
- Provide, maintain, and improve the Service
- Process payments and manage subscriptions
- Send service announcements, updates, and security alerts
- Provide customer support and respond to inquiries
- Comply with legal obligations and enforce our Terms of Service
- Improve our platform and features
3.3. End-User Data
We process End-User data solely on behalf of and according to the instructions of our Customers to:
- Generate AI-powered product tours
- Analyze application structure to create contextual guidance
- Provide analytics and insights to our Customers
- Improve the accuracy and relevance of tour generation
4. Data Usage and Model Training
We want to be transparent about how we use data:
- We may use aggregated, de-identified, and anonymized data to train and improve our internal models and enhance the Service
- We do not sell your data to third parties
- All data used for improvement is stripped of identifying information and cannot be traced back to any individual Customer or End-User
- Customers may opt in to share anonymized data to help improve tour generation quality (opt-in only)
5. Data Sharing and Disclosure
We may share your information in the following circumstances:
5.1. With Service Providers
We work with trusted third-party service providers who process data on our behalf, including infrastructure, payment processing, and communication services. All service providers are contractually obligated to protect your data and use it only for the purposes we specify.
5.2. With Customers
We provide Customers with analytics about how End-Users interact with generated tours, including engagement metrics, question patterns, and usage insights.
5.3. For Legal Compliance
We may disclose information if required to:
- Comply with applicable laws, regulations, or legal processes
- Respond to lawful requests from government authorities
- Protect our rights, property, or safety, or that of our users
- Enforce our Terms of Service
5.4. Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change.
6. Data Storage and Security
We implement industry-standard technical and organizational measures to protect your information, including:
- Encryption in transit and at rest
- Access controls and authentication mechanisms
- Regular security audits and vulnerability assessments
- Employee training on data protection and security practices
Your data is stored on secure infrastructure with data centers located in various regions worldwide.
We retain your information as follows:
- Website Visitor Data: Up to 24 months
- Customer Account Data: Duration of your account plus 90 days after closure
- Customer Application Data: According to Customer instructions or up to 90 days after termination
- Generated Tours: Duration of the Customer relationship unless deleted
- Backup Data: Up to 90 days in backup systems after deletion
7. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to other countries, we use appropriate safeguards such as Standard Contractual Clauses and Data Processing Addendums.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies, including:
- Essential Cookies: Required for the Service to function properly
- Analytics Cookies: Help us understand how visitors use our website
- Functional Cookies: Remember your preferences and settings
You can control cookies through your browser settings. However, disabling certain cookies may affect the functionality of the Service.
9. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Restriction: Request that we limit how we use your information
- Portability: Request a copy of your data in a machine-readable format
- Objection: Object to our processing of your information for certain purposes
- Withdraw Consent: Withdraw consent where we rely on consent as the legal basis
To exercise these rights, please contact us at hi@miseru.ai. We will respond to your request within 30 days.
For End-Users: If you are an End-User of a Customer's application, please contact that Customer directly to exercise your rights.
10. Data Processing Addendum
For Customers who process personal data subject to GDPR, CCPA, or other data protection laws, we offer a Data Processing Addendum (DPA) that includes Standard Contractual Clauses, security measures, and data protection obligations.
To request a DPA, please contact us at hi@miseru.ai.
11. Children's Privacy
Our Service is not intended for anyone under the age of 18. We do not knowingly collect personal information from children.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the CCPA:
- Right to know what personal information we collect, use, and disclose
- Right to request deletion of your personal information
- Right to opt-out of the "sale" of personal information (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at hi@miseru.ai.
13. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland, you have rights under:
- The General Data Protection Regulation (GDPR)
- UK GDPR and Data Protection Act 2018
- Swiss Federal Act on Data Protection
We process your data based on the following legal bases: performance of a contract, legitimate interests, consent (where applicable), or compliance with legal obligations.
You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated Privacy Policy on our website and updating the "Last updated" date.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:
Email: hi@miseru.ai